Junglewise Threat Intelligence

CVE-2023-36189: PYSEC-2023-110 - SQL injection vulnerability in langchain v.0.0.64 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain componen

CVE-2023-36189 · Severity: low · CVSS 3.1 · Published 2023-07-06

Technologies: langchain (PyPI). Vendors: PyPI.

Executive brief

SQL injection vulnerability in langchain v.0.0.64 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component.

Affected products

  • PyPI langchain

Related threats